ZeroHour

CVE-2026-78510

mass

Critical heap buffer overflow in Microsoft Word enables remote code execution

CVSS 3.1
9.8 critical
EPSS
<1%p59
Published
()
Modified
AI analysis

CVE-2026-78510 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that, per the CVSS vector, is reachable over a network without authentication, without user interaction, and without any special privileges. A memory-corruption condition in Word's processing can be triggered by an attacker who can reach the vulnerable component, causing a heap overflow that disrupts memory layout. Successful exploitation allows the attacker to execute arbitrary code in the context of the Word process, with high impact on confidentiality, integrity, and availability. Organizations running Word within Microsoft 365 Apps or perpetual Office 2016, 2019, 2021, or 2024 are in scope; specific affected build numbers are not stated in the available data and should be taken from Microsoft's advisory. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a ~1% probability of exploitation within 30 days.

What to do: Inventory endpoints for Microsoft 365 Apps and perpetual Office 2016/2019/2021/2024 installations and apply Microsoft's Word security updates for all affected versions as soon as they are published, prioritizing internet-reachable or document-processing-heavy systems given the network-exploitable, no-authentication CVSS vector. Until patched, verify that Office automatic updates are enabled and consider limiting exposure for high-risk hosts. Because there is no public PoC or known exploitation, treat this as high-priority patching rather than an active-incident response, and re-check KEV/EPSS for movement.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2016
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of users (Office/Microsoft 365 installed base exceeds 1 billion devices and several hundred million commercial seats) — Microsoft Office is one of the most widely deployed desktop productivity suites, with a publicly reported installed base of over a billion devices and Microsoft 365 commercial seats in the hundreds of millions, so any Word code-execution…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.